Privacy policy
Privacy policy
This Privacy policy explains how Leonem Limited OÜ processes personal data when you visit liore.ee, place or receive an order, use customer accounts or return services, contact us, subscribe to marketing, or participate in a LIORE collaboration.
1. Controller and contact
The controller is Leonem Limited OÜ, registration number 16166116, VAT number EE103014935, registered office and current business and complaints address Pöörise tn 12, 13520 Tallinn, Estonia.
Privacy requests may be sent to info@liore.ee. We may request information reasonably necessary to verify the requester's identity. Please do not send full payment-card numbers, online-banking credentials, passwords, identity-document copies, or unnecessary health information by email.
2. Personal data, purposes, and legal bases
We process the following data where relevant:
| Purpose | Data | Legal basis |
|---|---|---|
| Store, cart, checkout, orders, payment status, delivery, returns, refunds, and customer service | Name, email, telephone, billing and delivery addresses, cart and order contents, order number, payment method and status, delivery choice, account and communications data | Steps requested before entering a contract and performance of the sales contract |
| Payments and fraud prevention | Payment method, amount, currency, transaction reference, device and risk signals, and payment status. LIORE does not receive full card numbers or online-banking login credentials | Contract performance; legitimate interests in secure payments and fraud prevention; payment providers' own legal obligations |
| Accounting, tax, product safety, recalls, complaints, and legal claims | Invoice and transaction data, correspondence, evidence, product and batch/lot details, and information required by authorities | Legal obligations and establishing, exercising, or defending legal claims |
| Website security and essential operation | IP address, device and browser information, logs, security events, session, cart, language, country, account, and privacy-choice data | Legitimate interests in secure and reliable operation; contract performance; storage/access strictly necessary to provide the requested service |
| Analytics and personalisation | Cookie identifiers, page and interaction data, approximate location, device and campaign data | Consent where required |
| Email or similar direct marketing | Name, email, subscription and consent record, interactions, and preferences | Consent. Where applicable law permits marketing to an existing customer, legitimate interests may be used with a clear opt-out |
| Product reviews, surveys, and collaborations | Name, contact details, submitted content, social profile, audience or campaign data, compensation and tax details, and communications | Contract or steps before a contract; consent for optional publication or marketing uses; legitimate interests in managing the programme |
Product reviews are handled through Judge.me. When you submit a review, Judge.me processes your name, email address, rating, review text, and any optional photo or video. Judge.me processes data received from LIORE on our behalf and may act as an independent controller when you interact directly with Judge.me or when a Judge.me reviewer account is created for you. Your review and chosen display name may be published on liore.ee and Judge.me and may be shared with Shopify's Shop app or other review-distribution channels that are enabled. You can manage or delete a review through your Judge.me reviewer account or contact us at info@liore.ee. For Judge.me's own processing, see the Judge.me Privacy Policy.
Where a customer voluntarily reports an adverse reaction, the message may contain health information. We ask only for information necessary to assess and report product safety. We process such information with explicit consent where required and/or where necessary to comply with product-safety law or establish legal claims. It may be shared with the product's responsible person, manufacturer, supplier, insurer, healthcare or emergency services at the customer's request, or a competent authority where legally required.
3. Sources and required information
We receive data:
- directly from you;
- automatically from your browser, device, cookies, and use of the store;
- from Shopify, including through Shopify Payments, when it operates the storefront, checkout, customer account, privacy, return, or payment functions;
- from MakeCommerce/Maksekeskus AS and other payment providers selected at checkout;
- from carriers, parcel-machine operators, fulfilment partners, and partner warehouses;
- from fraud-prevention, analytics, advertising, review, email, or collaboration services that are actually enabled; and
- from public sources where relevant to a business collaboration or legal claim.
Information marked as required in checkout is needed to enter and perform the contract or comply with law. Without it, we may be unable to accept payment, issue a compliant invoice, deliver the order, process a return, or answer a legal claim. Creating a customer account and consenting to non-essential cookies or marketing are optional.
4. Recipients and service providers
Depending on the transaction and choices made, recipients may include:
- Shopify, which provides the online store, checkout, hosting, customer-account, privacy, return, Shop, Inbox, Point of Sale, Collective, and Collabs infrastructure where those services are enabled and, when Shopify Payments is used, processes customer payment data to provide payment processing, fraud screening, security, compliance, dispute, and related payment services;
- MakeCommerce, operated by Maksekeskus AS, which processes payment data for the methods it provides at checkout;
- the applicable payment processors and other payment-method providers identified at checkout;
- LHV Pank where manual bank transfer is used;
- carriers and parcel-machine operators, including Omniva and SmartPosti where selected;
- partner warehouses, suppliers, and fulfilment providers that need delivery information to fulfil an order;
- Google & YouTube, Facebook & Instagram, and Pinterest where the corresponding sales, catalogue, analytics, or advertising channel is enabled and the required consent or other lawful basis applies;
- Judge.me where review collection, display, verification, or review-request functions are enabled;
- other providers of email, hosting, customer service, analytics, advertising, fraud prevention, accounting, and collaboration tools that are actually enabled;
- professional advisers, insurers, auditors, banks, and debt-collection providers where necessary; and
- courts, law-enforcement bodies, tax authorities, consumer-protection, data-protection, customs, market-surveillance, and product-safety authorities where required by law.
When Shopify Payments is used, Shopify processes customer payment data to provide the payment services and may engage an applicable payment processor for that processing. Shopify and the applicable payment processor may also process personal data as independent controllers for specific purposes, including fraud and compliance screening, know-your-customer and anti-money-laundering checks, sanctions, payment-network rules, disputes, and other legal obligations. Their own privacy notices apply to that processing. Current information is available in the Shopify Consumer Privacy Policy and Shopify Payments payment processor list.
When MakeCommerce is selected, Leonem Limited OÜ transfers to Maksekeskus AS the personal data necessary to execute and support the payment, including the payer and contact details required for the selected method, amount, currency, order reference, and payment status. Maksekeskus AS may also process data under its own legal obligations and privacy notice.
Some recipients process data for Leonem Limited OÜ under a data-processing agreement. Others, including payment providers, banks, carriers, and public authorities, may act as independent controllers for their own legal and operational purposes. Their privacy notices apply to that processing.
We do not sell personal data.
5. International transfers
Shopify and another provider may process data outside the European Economic Area. Where GDPR requires a transfer safeguard, we rely on an applicable European Commission adequacy decision, Standard Contractual Clauses with any necessary supplementary measures, or another lawful GDPR Chapter V mechanism. Information about a particular safeguard or a copy where available may be requested at info@liore.ee.
Where a non-EEA fulfilment provider is used, its data-protection role and the applicable transfer safeguard will be confirmed before personal data is transferred to it.
6. Retention
We keep personal data only as long as necessary for the stated purpose, including:
- accounting records and underlying transaction documents: generally 7 years from the end of the relevant financial year or other statutory period;
- order, delivery, return, refund, customer-service, and complaint data: generally up to 3 years after the contract or case closes, and longer while a dispute, recall, authority request, or legal duty remains active;
- customer-account data: while the account is active and thereafter only for applicable contract, accounting, security, and claim periods;
- marketing subscription data: until consent is withdrawn or the subscription is otherwise ended; the record needed to prove consent or an objection may generally be retained for up to 3 years;
- collaboration records: for the agreement term and applicable accounting and claim periods;
- cookie and technical logs: according to the duration displayed in cookie preferences and, for security logs, generally no longer than 12 months unless an incident requires longer retention; and
- unsuccessful order or abandoned-checkout data: only for the period reasonably necessary for recovery, support, fraud prevention, consented marketing, or legal compliance.
We delete or anonymise data when the purpose and applicable retention period end.
7. Cookies and similar technologies
Strictly necessary technologies enable security, network management, the cart, checkout, language and region choices, customer accounts, and storage of privacy choices. They are used without consent only where legally permitted and necessary to provide the service requested.
Analytics, personalisation, and marketing technologies are used only after consent where consent is required. Cookie preferences identify the available categories and can be reopened through the Cookie preferences link in the footer. Withdrawing consent must be as easy as giving it. Withdrawal does not affect earlier lawful processing.
Browser settings may block cookies, but blocking strictly necessary storage can prevent the cart, checkout, account, or preference controls from working.
8. Your rights
Subject to the conditions in data-protection law, you may:
- obtain information about processing and a copy of your personal data;
- request correction of inaccurate or incomplete data;
- request erasure or restriction;
- receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller;
- object to processing based on legitimate interests;
- object at any time to direct marketing, including related profiling;
- withdraw consent at any time without affecting processing carried out before withdrawal; and
- request human review where a legally significant decision is based solely on automated processing.
Send a request to info@liore.ee. We normally respond within one month, subject to lawful extensions. Rights are not absolute; if a request cannot be fulfilled in full, we explain the reason and available remedies.
You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee, or another competent supervisory authority, particularly in the country where you live or work or where the alleged infringement occurred.
9. Automated decisions
Leonem Limited OÜ does not make customer decisions based solely on automated processing that produce legal or similarly significant effects. Payment and fraud-prevention providers may perform automated risk checks under their own notices. Contact us if an automated check appears to have caused a significant problem so that we can arrange human review where applicable.
10. Security
We use reasonable technical and organisational safeguards appropriate to the risk. No internet transmission or storage system is completely secure. Customers must protect their email account, one-time login codes, and account access and should contact us promptly if they suspect misuse.
11. Changes
We update this policy when processing, providers, or law changes. Material changes are communicated appropriately. The current version and date are published on the website.